🦞 OpenClaw Exposure Watchboard
This page lists publicly reachable active OpenClaw instances for defensive awareness. If this is your deployment, enable authentication, remove direct public exposure, and patch immediately.
Exposed Instances: 683295 Page: 963 / 6833 (100 per page) Showing: 96201-96300 Last Imported: 19/04/2026, 08:41:00
🇨🇳 364,448
🇺🇸 188,265
Build With Vivgrid
Explore Vivgrid Ship Secure Enterprise AI Agents 10× Faster with vivgrid.com
Vivgrid gives you authentication, model gateway, tool control, cost tracking, and enterprise observability — everything you need to ship AI agents safely at scale.
| Endpoint | Assistant Name | Country | auth_required | is_active | has_leaked_creds | asn | asn_name | org | first_seen | last_seen | asi_has_breach | asi_has_threat_actor | asi_threat_actors | asi_cves | asi_enriched_at | asi_domains |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 39.87.149.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS4837 | CHINA UNICOM China169 Backbone | China Unicom Shandong | 04/04/2026, 17:35:14 | 17/04/2026, 18:44:19 | Yes | No | - | CVE-2025-23419 | 11/04/2026, 01:57:54 | chinaunicom.cn |
| 43.159.34.•••:18789 | - | 🇸🇬 Singapore | - | true | Leaked | AS132203 | Tencent Building, Kejizhongyi Avenue | Aceville Pte Ltd | 04/04/2026, 17:35:13 | 16/04/2026, 11:24:51 | Yes | Yes | APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, El-Machete, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-10708, CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-14177, CVE-2025-14178, CVE-2025-14180, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 05/04/2026, 14:17:15 | tencent.com |
| 43.129.55.•••:18789 | - | 🇮🇩 Indonesia | Yes | true | Leaked | AS132203 | Tencent Building, Kejizhongyi Avenue | Aceville Pte Ltd | 04/04/2026, 17:35:13 | 14/04/2026, 05:14:51 | Yes | - | - | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387 | 07/04/2026, 11:28:28 | tencent.com |
| 60.182.96.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS4134 | Chinanet | ChinaNet Jinhua Node Network | 04/04/2026, 17:35:13 | 04/04/2026, 19:50:07 | - | - | - | - | - | - |
| 172.188.51.•••:18789 | - | 🇸🇬 Singapore | Yes | true | Clean | AS8075 | Microsoft Corporation | Cloud | 04/04/2026, 17:35:13 | 13/04/2026, 14:54:37 | - | - | - | - | - | - |
| 171.37.58.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS4837 | CHINA UNICOM China169 Backbone | China Unicom Guangxi | 04/04/2026, 17:35:13 | 04/04/2026, 19:50:07 | - | - | - | - | - | - |
| 104.49.67.•••:18789 | - | 🇺🇸 United States | Yes | true | Clean | AS7018 | AT&T Enterprises, LLC | AT&T Internet Services | 04/04/2026, 17:35:13 | 15/04/2026, 10:38:16 | No | No | - | - | 05/04/2026, 10:06:38 | - |
| 20.240.49.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 04/04/2026, 17:32:56 | 06/04/2026, 00:38:32 | No | No | - | - | 30/03/2026, 03:49:36 | - |
| 20.196.214.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 04/04/2026, 17:32:56 | 06/04/2026, 00:38:32 | No | Yes | APT28, APT35, APT37, APT39, Cobalt Group, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2016-10708, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617 | 05/04/2026, 03:49:37 | - |
| 175.178.106.•••:18789 | - | 🇨🇳 China mainland | - | true | Leaked | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud | 04/04/2026, 17:32:56 | 06/04/2026, 00:38:32 | Yes | Yes | APT37, El-Machete | CVE-2016-20012, CVE-2019-16905, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617 | 05/04/2026, 03:49:41 | tencent.com |
| 20.91.192.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 04/04/2026, 17:32:56 | 06/04/2026, 00:38:32 | Yes | No | - | - | 05/04/2026, 03:49:43 | duckdns.org |
| 2a02:4780:79:67f1::1:18789 | - | 🇩🇪 Germany | - | true | Clean | AS47583 | Hostinger International Limited | Hostinger | 04/04/2026, 17:32:56 | 18/04/2026, 00:37:02 | - | - | - | - | - | - |
| 138.197.8.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 04/04/2026, 17:32:56 | 18/04/2026, 00:36:14 | No | No | - | CVE-2018-20685, CVE-2019-16905, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617, CVE-2024-39894, CVE-2024-6387, CVE-2025-26466 | 05/04/2026, 03:49:45 | - |
| 34.122.206.•••:18789 | - | 🇺🇸 United States | Yes | true | Clean | AS396982 | Google LLC | 04/04/2026, 17:32:56 | 06/04/2026, 00:38:31 | No | Yes | DragonFly, Packrat | CVE-2016-20012, CVE-2019-16905, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 05/04/2026, 03:49:46 | - | |
| 20.91.232.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 04/04/2026, 17:32:55 | 06/04/2026, 00:38:31 | No | Yes | APT29, APT35, Callisto Group, Cobalt Group, MoustachedBouncer | CVE-2013-0340, CVE-2015-20107, CVE-2016-20012, CVE-2016-3189, CVE-2018-25032, CVE-2019-12900, CVE-2020-10735, CVE-2020-12062, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-28861, CVE-2021-29921, CVE-2021-36368, CVE-2021-3733, CVE-2021-3737, CVE-2021-41617, CVE-2022-0391, CVE-2022-37454, CVE-2022-42919, CVE-2022-45061, CVE-2023-24329, CVE-2023-27043 | 05/04/2026, 03:49:48 | - |
| 20.194.155.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 04/04/2026, 17:32:55 | 06/04/2026, 00:38:31 | - | - | - | - | - | - |
| 104.236.204.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 04/04/2026, 17:32:55 | 18/04/2026, 00:36:09 | No | No | - | - | 30/03/2026, 03:49:51 | - |
| 20.46.169.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 04/04/2026, 17:32:55 | 06/04/2026, 00:38:31 | - | - | - | - | - | - |
| 104.46.219.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 04/04/2026, 17:32:55 | 06/04/2026, 00:38:31 | - | - | - | - | - | - |
| 82.165.149.•••:18789 | - | 🇫🇷 France | Yes | true | Clean | AS8560 | This is the joint network for IONOS, Fasthosts, Arsys, 1&1 Mail and Media and 1&1 Telecom. Formerly known as 1&1 Internet SE. | IONOS Cloud NBZ | 04/04/2026, 17:32:55 | 06/04/2026, 00:38:31 | No | No | - | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 05/04/2026, 03:49:55 | - |
| 20.112.12.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 04/04/2026, 17:32:55 | 06/04/2026, 00:38:31 | - | - | - | - | - | - |
| 20.196.96.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 04/04/2026, 17:32:55 | 06/04/2026, 00:38:31 | - | - | - | - | - | - |
| 54.179.182.•••:18789 | - | 🇸🇬 Singapore | Yes | true | Clean | AS16509 | Amazon.com, Inc. | Amazon | 04/04/2026, 17:32:55 | 06/04/2026, 00:38:31 | No | Yes | APT28, APT35, APT37, APT39, Cobalt Group, Kimsuky, Mustang Panda, Sandworm Team, The Shadow Brokers | CVE-2016-10708, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617, CVE-2025-23419 | 05/04/2026, 03:50:01 | - |
| 106.15.64.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 04/04/2026, 17:32:55 | 06/04/2026, 00:38:31 | Yes | No | - | - | 05/04/2026, 03:50:02 | aliyun.com |
| 13.73.7.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 04/04/2026, 17:32:55 | 06/04/2026, 00:38:31 | - | - | - | - | - | - |
| 56.69.26.•••:18789 | - | 🇲🇾 Malaysia | - | true | Clean | AS16509 | Amazon.com, Inc. | Amazon Data Services | 04/04/2026, 17:32:55 | 17/04/2026, 20:06:19 | - | - | - | - | - | - |
| 40.124.27.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 04/04/2026, 17:32:55 | 06/04/2026, 00:38:31 | No | No | - | - | 30/03/2026, 03:50:07 | - |
| 20.89.96.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 04/04/2026, 17:32:55 | 06/04/2026, 00:38:31 | No | Yes | APT15, APT28, APT29, APT31, APT34, APT41, Bitter APT, Bluenoroff, Callisto Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, Volt Typhoon | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385 | 05/04/2026, 03:50:08 | - |
| 4.215.214.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 04/04/2026, 17:32:55 | 06/04/2026, 00:38:31 | No | No | - | - | 30/03/2026, 03:50:09 | - |
| 61.14.209.•••:18789 | - | 🇰🇷 South Korea | - | true | Clean | AS45382 | Hostcenter | Hostcenter | 04/04/2026, 17:32:55 | 06/04/2026, 00:38:31 | Yes | Yes | APT14, APT28, APT40, APT41, Cobalt Group, Gamaredon Group, IronHusky, Kimsuky, Lazarus Group, SharpPanda, TA505, WIRTE | CVE-2006-20001, CVE-2019-17567, CVE-2020-11984, CVE-2020-11993, CVE-2020-13938, CVE-2020-13950, CVE-2020-1927, CVE-2020-1934, CVE-2020-35452, CVE-2020-9490, CVE-2021-23017, CVE-2021-26690, CVE-2021-26691, CVE-2021-30641, CVE-2021-33193, CVE-2021-34798, CVE-2021-36160, CVE-2021-3618, CVE-2021-39275, CVE-2021-40438, CVE-2021-44224, CVE-2021-44790, CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-23943, CVE-2022-26377, CVE-2022-28330, CVE-2022-28614, CVE-2022-28615, CVE-2022-29404, CVE-2022-30556, CVE-2022-31813, CVE-2022-36760, CVE-2022-37436, CVE-2022-41741, CVE-2022-41742, CVE-2023-25690, CVE-2023-27522, CVE-2023-31122, CVE-2023-38709, CVE-2023-44487, CVE-2023-45802, CVE-2024-12254, CVE-2024-12718, CVE-2024-24795, CVE-2024-27316, CVE-2024-3219, CVE-2024-38472, CVE-2024-38473, CVE-2024-38474, CVE-2024-38475, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573, CVE-2024-40898, CVE-2024-7347, CVE-2024-7592, CVE-2024-8088, CVE-2024-9287, CVE-2025-12084, CVE-2025-12781, CVE-2025-13836, CVE-2025-13837, CVE-2025-23419 | 05/04/2026, 03:50:11 | hostcenter.co.kr |
| 13.60.6.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS16509 | Amazon.com, Inc. | Amazon Data Services Sweden | 04/04/2026, 17:32:54 | 17/04/2026, 08:29:59 | No | No | - | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 05/04/2026, 03:50:13 | - |
| 209.38.43.•••:18789 | - | 🇳🇱 Netherlands | - | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 04/04/2026, 17:32:54 | 17/04/2026, 22:22:26 | No | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 05/04/2026, 03:50:14 | - |
| 43.167.217.•••:18789 | - | 🇸🇬 Singapore | - | true | Leaked | AS132203 | Tencent Building, Kejizhongyi Avenue | Aceville Pte Ltd | 04/04/2026, 17:32:54 | 06/04/2026, 00:38:30 | Yes | No | - | CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 05/04/2026, 03:50:15 | tencent.com |
| 20.65.243.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 04/04/2026, 17:32:54 | 06/04/2026, 00:38:30 | - | - | - | - | - | - |
| 101.52.218.•••:18789 | - | 🇨🇳 China mainland | - | true | Clean | AS17621 | China Unicom Shanghai network / AS4811 China Telecom (Group) | GDS Changan Services | 04/04/2026, 17:32:54 | 08/04/2026, 22:00:39 | - | - | - | - | - | - |
| 20.240.235.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 04/04/2026, 17:32:54 | 06/04/2026, 00:38:30 | No | No | - | - | 30/03/2026, 03:50:20 | - |
| 8.219.182.•••:18789 | - | 🇸🇬 Singapore | Yes | true | Clean | AS45102 | Alibaba (US) Technology Co., Ltd. | Alibaba Cloud Singapore | 04/04/2026, 17:32:54 | 06/04/2026, 01:23:33 | No | Yes | APT15, APT17, APT28, APT29, APT31, APT34, APT35, APT36, APT37, APT40, APT41, APT45, Bitter APT, Bluenoroff, Callisto Group, Carbanak, ChamelGang, CloudSorcerer, Daggerfly APT, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-20012, CVE-2020-12062, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387 | 05/04/2026, 03:50:22 | - |
| 104.21.83.•••:18789 | - | 🇺🇸 United States | - | true | Leaked | AS13335 | Cloudflare, Inc. | Cloudflare | 04/04/2026, 17:32:54 | 06/04/2026, 01:23:33 | Yes | No | - | - | 05/04/2026, 03:50:23 | empowerinstitutional.com, 1-x-stavka1.ru, fuyuanwj.com, danca.tv, venancio.com, macrosfastening.com, jxxlxj.com, abainfra.net, styled.fr, atcevents.com, ashley.fr, classicelectricomaha.com, tenxtenx.com, cwsse.com.cn, leap.fr, sdkyjt.net, luckyplastic.net, ics-line.com, flexipgroup.com, electronicengineering.com, ligneblanche.fr, aiden-vn.com, allbritten.com, erbium.fr, anhbac.com, gws.fr, daso.fr, sz-jl.com, hoyavision.com.ar, quatangthanhdong.com, bbbiotechconference.com, bianchi.fr, woodgateneighbors.com, hbbygd88.com, efreyre.com, africa.com, globalmattersgroup.com, cityfied.net, personalcapital.com, gx101.com, takemurass.com, alfamak.com, rightwaytrading.net, xintec.hk, factotum.fr, wenchyuan.com, fujiyama.fr, medtecjapan.com, meter.ln.cn, anlink.net, jxygcy.com, nitro.fr, jindianglass.net, knottlab.com, gipnutmeg.com, xjhhcm.com, lesmouettes.fr, ytxweb.net, licenseglobal.com, paolino.fr, wintersuninternational.com, naseni.gov.ng, judgeyachts.com, aurus.fr, cayman.fr, mcconstructors.com, clubduma.ru, audiencegain.net, retrievalmasters.com, chinasyh.net, lateteailleurs.fr, leonne.fr, taxi321.com, apropos.fr, tanagerwealth.com, wisehousetech.com, cloudflare.net, ipe.org.br, uniquestaxidermy.com, pontoon.fr, ohe.fr, gatorchucks.cn, hanofoods.com, co.com, activ.fr, kidsbud.net, lebistrotduport.fr, loitoan.com, sherry.fr, aviationnow.com, innfos.cn, feedstuffs.com, altosdelchicala.com, gloriouscolor.com, baselinewoods.com, precision.fr, yin.fr, devil.fr, alghanitex.com, christen.fr, qzz.io, isotope.fr, greatwest.com, dehuiguangchang.cn, incidence.fr, nursinghomerating.org, xjgudao.com, telos.fr, siblighting.com, porcelainchina.net, brownsprinting.com, expocihac.com, oceans.fr, phutho.work, m-printone.com, zach.fr, cloudhq-mkt6.net, storia.fr, champmar-ec.com, t-zoneland.com, forwardwirecloth.net, songhycas.com, timing-tech.com, lepicier.fr, noon.fr, us.org, wantaig.com.tw, efi.fr, muabanten.com, woodworksrefinish.com, ares-argentina.com.ar, aerosupplycargosadecv.com, mayhoangtung.com, wenn.com, chinayinshufood.com, mondi.fr, turlututu.fr, flaneur.fr, teppanyaki.fr, avc.fr, gialoilongan.com, leisonhk.com, refee.net, xjzljt.net, prgnpi.com, dongfanggufen.net, goin-vn.com, wakechem.com, zenna.fr, delco-construction.com, vsun-solar.com, indonga.net, amedee.fr, empower.me, qyqlgs.com, hansel.fr, cyberlotus.com, plasto.fr, sinotransfj.com, serio.fr, vrgkhaihoan.com, dzrjx.net, empowermeetings.com, medequips.org, aptenonsjz.com, nada.fr, eurostampiparma.it, greatwesttrustco.com, athenee.fr, akina.fr, umberto.fr, essex.fr, www.us.com, ibcglobal.com, hardi.fr, dldianfeng.cn, simatek.com, bamko.net, fabi.fr, inventaire.fr, hansecontrol.com, keshardeo.com, retailtrafficmag.com, geole.fr, cphi.com, it.com, voyagevietnammoto.com, lamaxwell.com, vimedtec.com, viettelsoftware.com, hanacans.com, itb.fr, pumpkin.fr, oukay.net, cuacuonanbinh.com, aigmf.com, boxboard.com, ichiisoft.com, splendid-hotel.fr, beiyuecheng.com, www.eu.com, sym.fr, china-one.net, kingdisplay.net, chuyenphatnhanhgiare.net, jssd.net, duranttool.com, eu.org, mullintbg.com, amilcar.fr, jadzdjm.com, pprossmx.com, polikom.ru, mero.fr, otisa.com, com.de, rgcinversiones.com.ar, mandarinoriental.it, hancockalbanese.com, mydhaga.com, www.de.com, atsengineering.net, ceramic.fr, doradver.ru, maginus.com, tahaluf.com, barnesdennig.com, gwl.com, jason.fr, newyorkfarmshow.com, richlandtexas.gov, aldente.fr, szlis.com.cn, pastelfd.com.ar, sharedadventures.org, aciervanguard.com, dvipcdn.com, cheers.fr, huadewood.com, juancprieto.com, sqempresas.cl, leverijllc.com, mirror.fr, parliament-osetia.ru, oneway.fr, xjnmi.com, casablanca.fr, oracle-ag.ch, eyes-armour.com, zhaowoo.net, jiangsufuji.com, famekeeda.com, arista.fr, grandplace.fr, transpacificvn.com, iirusa.com, natasaspa.com, admtoronto.com, frogs.fr, comestibles.fr, electrode.fr, gunguntextiles.com, cercle-entreprise.fr, fxgowin.com, nash.fr, freda.fr, agriglobalcommodity.com, airtkt.com, handy.fr, aiglon.fr, eushipments.com, aout.fr, cariboo.fr, workers.dev, optiontrax.com, hashemfoods.com, indianscientificgoods.com, reva.fr, newoceanfood.com, nttdata-vds.com, dechuangjixie.com, cnkejie.com, mallyas.com, technos.fr, thenewthings.com, 8189330.cn, canalrivertrust.org.uk, jinpac.com, audito.fr, cloudns.net, anmacvietnam.com, proximus.fr, maymacanphu.com, petitspois.fr, rpmwatercraft.com, jucyvietnam.com, sibur-traektoria.ru, co.zm, piqueassiette.fr, pollyholding.com, allaboutnails.org, anhuaabrasives.net, disa.fr, exponentiel.fr, liyubelt.net.cn, zsnet.net, topigx.com, gaolongan.com, sdfengze.net, canontradeshows.com, designnews.com, monreve.fr, informamarkets-info.com, tenor.fr, flushbottomvalves.net, canadalifeus.com, mariano.fr, vladimir.fr, exceptions.fr, airfuture.com, vinagreenplus.com, futurefg.ru, arcgroup.com, money2020middleeast.com, hy189.net, erostours.com, chinakangtai.net, ike.fr, isofh.com, prestigestarcarpet.com, lecottage.fr, loginport.com, lyric-line.ru, jilyphukhai.com, geochem.org, food-machines.net, whir.com, greenviet.net, alptech.fr, chothuemaylamda.com, dmln.net, intertec.com |
| 20.225.214.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 04/04/2026, 17:32:54 | 06/04/2026, 01:23:33 | - | - | - | - | - | - |
| 47.250.199.•••:18789 | - | 🇺🇸 United States | - | true | Clean | AS45102 | Alibaba (US) Technology Co., Ltd. | Alibaba Cloud | 04/04/2026, 17:32:54 | 06/04/2026, 01:23:33 | - | - | - | - | - | - |
| 51.12.93.•••:18789 | - | 🇪🇺 European Union | - | true | Clean | AS8075 | Microsoft Corporation | Cloud | 04/04/2026, 17:32:54 | 06/04/2026, 01:23:33 | No | No | - | - | 30/03/2026, 03:50:27 | - |
| 112.74.60.•••:18789 | - | 🇨🇳 China mainland | - | true | Leaked | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 04/04/2026, 17:32:54 | 06/04/2026, 01:23:33 | Yes | Yes | APT-C-23, APT-C-50, APT15, APT17, APT28, APT29, APT31, APT34, APT35, APT36, APT37, APT39, APT40, APT41, APT45, Bitter APT, Bluenoroff, Callisto Group, Carbanak, ChamelGang, CloudSorcerer, Cobalt Group, Daggerfly APT, Domestic Kitten, Donot Team, Earth Berberoka, Equation Group, Gamaredon Group, Gaza Cybergang, Ghostwriter, Hafnium Group, Inception Framework, Kimsuky, Lazarus Group, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, TA428, The Shadow Brokers, Turla APT Group, Volt Typhoon | CVE-2006-7243, CVE-2007-1581, CVE-2007-3799, CVE-2007-4658, CVE-2007-6750, CVE-2008-0455, CVE-2009-2626, CVE-2009-2687, CVE-2009-2699, CVE-2009-3094, CVE-2009-3095, CVE-2009-3291, CVE-2009-3292, CVE-2009-3293, CVE-2009-3555, CVE-2009-3557, CVE-2009-3558, CVE-2009-4018, CVE-2009-4142, CVE-2009-4143, CVE-2009-4418, CVE-2009-5016, CVE-2010-0408, CVE-2010-0434, CVE-2010-1128, CVE-2010-1129, CVE-2010-1130, CVE-2010-1452, CVE-2010-1860, CVE-2010-1861, CVE-2010-1862, CVE-2010-1864, CVE-2010-1868, CVE-2010-1914, CVE-2010-1915, CVE-2010-1917, CVE-2010-2093, CVE-2010-2097, CVE-2010-2100, CVE-2010-2101, CVE-2010-2190, CVE-2010-2191, CVE-2010-2225, CVE-2010-2484, CVE-2010-2531, CVE-2010-3065, CVE-2010-3436, CVE-2010-3709, CVE-2010-3710, CVE-2010-3870, CVE-2010-4150, CVE-2010-4645, CVE-2010-4657, CVE-2010-4697, CVE-2010-4698, CVE-2010-4699, CVE-2011-0419, CVE-2011-0421, CVE-2011-0708, CVE-2011-0752, CVE-2011-0755, CVE-2011-1092, CVE-2011-1153, CVE-2011-1464, CVE-2011-1466, CVE-2011-1467, CVE-2011-1468, CVE-2011-1469, CVE-2011-1470, CVE-2011-2483, CVE-2011-3182, CVE-2011-3192, CVE-2011-3267, CVE-2011-3268, CVE-2011-3348, CVE-2011-3368, CVE-2011-3607, CVE-2011-3639, CVE-2011-4317, CVE-2011-4415, CVE-2011-4718, CVE-2011-4885, CVE-2012-0031, CVE-2012-0053, CVE-2012-0057, CVE-2012-0788, CVE-2012-0789, CVE-2012-0883, CVE-2012-1171, CVE-2012-1172, CVE-2012-1823, CVE-2012-2143, CVE-2012-2311, CVE-2012-2336, CVE-2012-2687, CVE-2012-2688, CVE-2012-3365, CVE-2012-3499, CVE-2012-4557, CVE-2012-4558, CVE-2013-1635, CVE-2013-1643, CVE-2013-1862, CVE-2013-1896, CVE-2013-2110, CVE-2013-4248, CVE-2013-4635, CVE-2013-5704, CVE-2013-6438, CVE-2014-0098, CVE-2014-0118, CVE-2014-0226, CVE-2014-0231, CVE-2014-0237, CVE-2014-0238, CVE-2014-9427, CVE-2015-8994, CVE-2016-10708, CVE-2016-20012, CVE-2016-4975, CVE-2016-5387, CVE-2016-7478, CVE-2016-8743, CVE-2017-15906, CVE-2017-3167, CVE-2017-3169, CVE-2017-7679, CVE-2017-9788, CVE-2017-9798, CVE-2018-15473, CVE-2018-15919, CVE-2018-19395, CVE-2018-19396, CVE-2018-19520, CVE-2018-20685, CVE-2019-16905, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-23017, CVE-2021-3618, CVE-2021-36368, CVE-2021-41617, CVE-2022-41741, CVE-2022-41742, CVE-2023-28531, CVE-2023-38408, CVE-2023-44487, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-24990, CVE-2024-31079, CVE-2024-32760, CVE-2024-34161, CVE-2024-35200, CVE-2024-6387, CVE-2024-7347, CVE-2025-26465, CVE-2025-32728 | 05/04/2026, 03:50:28 | aliyun.com |
| 51.48.149.•••:5503 | - | 🇪🇸 Spain | Yes | true | Clean | AS16509 | Amazon.com, Inc. | Unknown | 04/04/2026, 17:00:10 | 18/04/2026, 00:03:57 | - | - | - | - | - | - |
| 52.180.68.•••:18789 | - | 🇺🇸 United States | Yes | true | Clean | AS8075 | Microsoft Corporation | Microsoft | 04/04/2026, 16:57:52 | 09/04/2026, 13:10:23 | No | No | - | CVE-2018-20685, CVE-2019-16905, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617 | 04/04/2026, 17:05:38 | - |
| 207.180.248.•••:18789 | - | 🇩🇪 Germany | Yes | true | Clean | AS51167 | Contabo GmbH | Contabo | 04/04/2026, 16:55:19 | 04/04/2026, 19:55:05 | - | - | - | - | - | - |
| 64.225.51.•••:443 | - | 🇺🇸 United States | Yes | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 04/04/2026, 16:55:18 | 15/04/2026, 11:22:23 | No | Yes | APT14, APT15, APT28, APT29, APT31, APT34, APT40, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, IronHusky, Kimsuky, Lazarus Group, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SharpPanda, SideWinder APT, TA505, Volt Typhoon, WIRTE | CVE-2006-20001, CVE-2016-10009, CVE-2016-10010, CVE-2016-10011, CVE-2016-10012, CVE-2016-10708, CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-17567, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-11984, CVE-2020-11993, CVE-2020-12062, CVE-2020-13938, CVE-2020-13950, CVE-2020-14145, CVE-2020-15778, CVE-2020-1927, CVE-2020-1934, CVE-2020-35452, CVE-2020-9490, CVE-2021-23017, CVE-2021-26690, CVE-2021-26691, CVE-2021-28041, CVE-2021-30641, CVE-2021-33193, CVE-2021-34798, CVE-2021-36160, CVE-2021-3618, CVE-2021-36368, CVE-2021-39275, CVE-2021-40438, CVE-2021-41617, CVE-2021-44224, CVE-2021-44790, CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-23943, CVE-2022-26377, CVE-2022-28330, CVE-2022-28614, CVE-2022-28615, CVE-2022-29404, CVE-2022-30556, CVE-2022-31813, CVE-2022-36760, CVE-2022-37436, CVE-2022-41741, CVE-2022-41742, CVE-2023-25690, CVE-2023-27522, CVE-2023-28531, CVE-2023-31122, CVE-2023-38408, CVE-2023-38709, CVE-2023-44487, CVE-2023-45802, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-24795, CVE-2024-27316, CVE-2024-6387, CVE-2024-7347, CVE-2025-23419, CVE-2025-26465, CVE-2025-32728 | 08/04/2026, 02:39:05 | - |
| 42.51.34.•••:50000 | - | 🇨🇳 China mainland | Yes | true | Clean | AS56005 | Zhengzhou Fastidc Technology Co.,Ltd. | Henan Telcom Union Technology | 04/04/2026, 16:55:18 | 17/04/2026, 05:36:59 | No | No | - | - | 01/04/2026, 17:14:47 | - |
| 2a02:4780:2d:2553::1:443 | - | 🇺🇸 United States | - | true | Clean | AS47583 | Hostinger International Limited | Hostinger | 04/04/2026, 16:55:18 | 04/04/2026, 19:55:04 | - | - | - | - | - | - |
| 104.248.164.•••:443 | - | 🇬🇧 United Kingdom | Yes | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 04/04/2026, 16:55:18 | 17/04/2026, 23:57:24 | No | Yes | APT15, APT28, APT29, APT31, APT34, APT41, Bitter APT, Bluenoroff, Callisto Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, Volt Typhoon | CVE-2016-20012, CVE-2020-12062, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728 | 05/04/2026, 08:22:08 | - |
| 88.99.107.•••:18789 | - | 🇩🇪 Germany | Yes | true | Clean | AS24940 | Hetzner Online GmbH | Hetzner | 04/04/2026, 16:55:17 | 17/04/2026, 00:21:11 | - | - | - | - | - | - |
| 139.196.243.•••:2026 | - | 🇨🇳 China mainland | Yes | true | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 04/04/2026, 16:55:17 | 16/04/2026, 16:02:31 | No | No | - | - | 04/04/2026, 11:43:15 | - |
| 170.64.215.•••:18789 | - | 🇦🇺 Australia | Yes | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 04/04/2026, 16:55:17 | 16/04/2026, 01:24:01 | No | Yes | APT15, APT17, APT28, APT31, APT36, APT37, APT45, Bitter APT, Bluenoroff, Callisto Group, CloudSorcerer, Daggerfly APT, Donot Team, Gamaredon Group, Gaza Cybergang, Inception Framework, Kimsuky, MuddyWater Group, RomCom Group, Salt Typhoon, Sea Turtle Group, SideWinder APT, The Shadow Brokers | CVE-2016-20012, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-44487, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2024-7347, CVE-2025-23419, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 08/04/2026, 02:39:55 | - |
| 2a02:4780:66:be60::1:18789 | - | 🇧🇷 Brazil | - | true | Clean | AS47583 | Hostinger International Limited | Hostinger | 04/04/2026, 16:55:17 | 08/04/2026, 04:06:13 | - | - | - | - | - | - |
| 101.37.64.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 04/04/2026, 16:55:17 | 17/04/2026, 20:13:50 | Yes | No | - | - | 08/04/2026, 01:50:39 | aliyun.com |
| 36.170.100.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS9808 | China Mobile Communications Group Co., Ltd. | China Mobile | 04/04/2026, 16:55:17 | 04/04/2026, 19:55:03 | - | - | - | - | - | - |
| 139.196.161.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 04/04/2026, 16:55:16 | 04/04/2026, 19:55:03 | - | - | - | - | - | - |
| 136.115.2.•••:443 | - | 🇺🇸 United States | Yes | true | Clean | AS396982 | Google LLC | 04/04/2026, 16:55:16 | 16/04/2026, 20:35:27 | No | No | - | - | 02/04/2026, 04:56:41 | - | |
| 159.65.82.•••:443 | - | 🇬🇧 United Kingdom | Yes | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 04/04/2026, 16:55:16 | 05/04/2026, 16:32:59 | No | Yes | APT14, APT15, APT17, APT28, APT29, APT31, APT34, APT35, APT36, APT37, APT40, APT41, APT45, Bitter APT, Bluenoroff, Callisto Group, Carbanak, ChamelGang, CloudSorcerer, Cobalt Group, Daggerfly APT, Donot Team, Equation Group, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, IronHusky, Kimsuky, Lazarus Group, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SharpPanda, SideWinder APT, TA505, The Shadow Brokers, UNC2452, Volt Typhoon, WIRTE | CVE-2016-20012, CVE-2019-17567, CVE-2020-11984, CVE-2020-11993, CVE-2020-12062, CVE-2020-13950, CVE-2020-14145, CVE-2020-15778, CVE-2020-1927, CVE-2020-1934, CVE-2020-35452, CVE-2020-9490, CVE-2021-26690, CVE-2021-26691, CVE-2021-28041, CVE-2021-30641, CVE-2021-33193, CVE-2021-34798, CVE-2021-36160, CVE-2021-36368, CVE-2021-39275, CVE-2021-40438, CVE-2021-41617, CVE-2021-44224, CVE-2021-44790, CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-23943, CVE-2022-26377, CVE-2022-28614, CVE-2022-28615, CVE-2022-29404, CVE-2022-30522, CVE-2022-30556, CVE-2022-31813, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 05/04/2026, 11:20:14 | - |
| 115.191.28.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS137718 | Beijing Volcano Engine Technology Co., Ltd. | Beijing Volcano Engine Technology | 04/04/2026, 16:55:16 | 16/04/2026, 01:23:07 | - | - | - | - | - | - |
| 104.247.76.•••:5310 | - | 🇭🇰 Hong Kong | Yes | true | Leaked | AS54641 | InMotion Hosting, Inc. | InMotion Hosting | 04/04/2026, 16:55:16 | 14/04/2026, 10:34:06 | Yes | Yes | APT-C-23, APT10, APT15, APT19, APT27, APT28, APT29, APT30, APT33, APT34, APT35, APT37, APT39, APT40, APT41, APT5, AQUATIC PANDA, Antlion APT, BRONZE ATLAS, Bluenoroff, Bronze Butler APT, Buhtrap Group, Carbanak, Cobalt Group, CopyKittens, DarkHydrus, DragonOK APT, Earth Berberoka, Energetic Bear, Equation Group, Gamaredon Group, Greenbug Group, Hafnium Group, Inception Framework, Kimsuky, Konni Group, Lazarus Group, Moses Staff APT, MuddyWater Group, Mustang Panda, Orangeworm, Sandworm Team, Silence Hacker Group, TA505, The Shadow Brokers, Thrip APT, Triton APT, Tropic Trooper, Volatile Kitten | CVE-2014-3562, CVE-2014-4650, CVE-2015-3456, CVE-2015-5741, CVE-2015-6815, CVE-2016-10708, CVE-2016-2124, CVE-2016-2183, CVE-2016-6662, CVE-2017-1000376, CVE-2017-15906, CVE-2017-5645, CVE-2017-9953, CVE-2018-1059, CVE-2018-10869, CVE-2018-10892, CVE-2018-10926, CVE-2018-1111, CVE-2018-1128, CVE-2018-1129, CVE-2018-14462, CVE-2018-14463, CVE-2018-14465, CVE-2018-14469, CVE-2018-14622, CVE-2018-14645, CVE-2018-14879, CVE-2018-14882, CVE-2018-15473, CVE-2018-15919, CVE-2018-16229, CVE-2018-16540, CVE-2018-16871, CVE-2018-17456, CVE-2018-18311, CVE-2018-20615, CVE-2018-20685, CVE-2018-3665, CVE-2018-3760, CVE-2018-5741, CVE-2018-5743, CVE-2018-5744, CVE-2019-10196, CVE-2019-11038, CVE-2019-11477, CVE-2019-11478, CVE-2019-14813, CVE-2019-14816, CVE-2019-14907, CVE-2019-19906, CVE-2019-3459, CVE-2019-3880, CVE-2019-5798, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2019-6470, CVE-2019-6471, CVE-2019-6974, CVE-2019-7221, CVE-2019-7317, CVE-2020-10696, CVE-2020-10711, CVE-2020-10749, CVE-2020-10756, CVE-2020-10763, CVE-2020-14145, CVE-2020-14318, CVE-2020-14355, CVE-2020-14364, CVE-2020-14370, CVE-2020-14394, CVE-2020-15705, CVE-2020-15706, CVE-2020-15707, CVE-2020-1711, CVE-2020-25639, CVE-2020-25657, CVE-2020-25710, CVE-2020-25717, CVE-2020-25743, CVE-2020-27777, CVE-2020-27786, CVE-2020-27827, CVE-2020-35518, CVE-2020-35524, CVE-2020-8616, CVE-2020-8617, CVE-2020-8622, CVE-2020-8623, CVE-2020-8624, CVE-2020-8625, CVE-2021-20179, CVE-2021-20188, CVE-2021-20229, CVE-2021-20236, CVE-2021-20270, CVE-2021-32027, CVE-2021-3516, CVE-2021-3532, CVE-2021-3533, CVE-2021-3537, CVE-2021-3621, CVE-2021-3669, CVE-2021-3737, CVE-2021-3752, CVE-2021-4104, CVE-2021-41617, CVE-2021-41817, CVE-2021-44142, CVE-2021-45417, CVE-2022-0711, CVE-2022-1011, CVE-2022-1227, CVE-2022-1708, CVE-2022-2132, CVE-2022-2393, CVE-2022-2850, CVE-2022-2989, CVE-2022-2990, CVE-2022-32545, CVE-2022-32546, CVE-2022-38178, CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 08/04/2026, 01:51:11 | inmotionhosting.com |
| 219.143.143.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS4847 | China Networks Inter-Exchange | ChinaNet | 04/04/2026, 16:55:16 | 08/04/2026, 10:06:51 | Yes | No | - | - | 08/04/2026, 07:54:48 | bj189.cn, 118114.cn, ctwing.cn, chinatelecom.com.cn, chinatelecom.cn, new-gm.cn, 189.cn, 189free.cn, ideal.sh.cn, daqu.com.cn, ctyun.cn |
| 2a02:4780:6e:b763::1:80 | - | 🇧🇷 Brazil | - | true | Clean | AS47583 | Hostinger International Limited | Hostinger | 04/04/2026, 16:55:15 | 16/04/2026, 19:04:17 | - | - | - | - | - | - |
| 2a02:4780:7:8e5b::1:18789 | - | 🇫🇷 France | - | true | Clean | AS47583 | Hostinger International Limited | Hostinger | 04/04/2026, 16:55:15 | 04/04/2026, 19:55:01 | - | - | - | - | - | - |
| 85.137.52.•••:18789 | - | 🇳🇱 Netherlands | Yes | true | Clean | AS43641 | SOLLUTIUM EU Sp z.o.o. | Virtual Systems | 04/04/2026, 16:55:15 | 16/04/2026, 01:22:51 | No | No | - | - | 07/04/2026, 12:20:02 | - |
| 157.230.139.•••:18789 | - | 🇺🇸 United States | Yes | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 04/04/2026, 16:55:15 | 17/04/2026, 01:06:15 | No | No | - | - | 04/04/2026, 15:37:23 | - |
| 156.225.21.•••:18789 | - | 🇺🇸 United States | Yes | true | Clean | AS401701 | cognetcloud INC | Vapeline Technology | 04/04/2026, 16:55:15 | 04/04/2026, 19:55:01 | - | - | - | - | - | - |
| 207.244.241.•••:21272 | - | 🇺🇸 United States | Yes | true | Leaked | AS40021 | Contabo Inc. | Contabo | 04/04/2026, 16:55:14 | 16/04/2026, 21:20:37 | Yes | Yes | APT14, APT15, APT17, APT28, APT29, APT31, APT34, APT35, APT36, APT37, APT40, APT41, APT45, Bitter APT, Bluenoroff, Callisto Group, Carbanak, ChamelGang, CloudSorcerer, Daggerfly APT, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2001-1556, CVE-2002-0061, CVE-2002-0392, CVE-2003-0020, CVE-2003-0083, CVE-2003-0132, CVE-2004-0174, CVE-2004-0942, CVE-2004-2343, CVE-2005-3352, CVE-2006-20001, CVE-2006-5752, CVE-2007-3304, CVE-2007-4465, CVE-2007-6750, CVE-2008-2939, CVE-2009-3555, CVE-2011-0419, CVE-2012-0031, CVE-2012-0053, CVE-2013-1862, CVE-2015-0228, CVE-2016-20012, CVE-2016-8612, CVE-2017-9788, CVE-2017-9798, CVE-2018-1301, CVE-2018-1302, CVE-2018-1303, CVE-2020-12062, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-34798, CVE-2021-36368, CVE-2021-39275, CVE-2021-40438, CVE-2021-41617, CVE-2021-44790, CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-28330, CVE-2022-28614, CVE-2022-28615, CVE-2022-29404, CVE-2022-30556, CVE-2022-31813, CVE-2022-37436, CVE-2023-28531, CVE-2023-31122, CVE-2023-38408, CVE-2023-38709, CVE-2023-44487, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-40898, CVE-2024-6387, CVE-2024-7347, CVE-2025-23419, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 10/04/2026, 09:36:39 | classyng.com, contaboserver.net, contabo.com, contabo.net |
| 149.104.31.•••:18789 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS139659 | LUCIDACLOUD LIMITED | Starcloud Global | 04/04/2026, 16:55:14 | 04/04/2026, 19:55:00 | - | - | - | - | - | - |
| 146.59.153.•••:18789 | - | 🇫🇷 France | Yes | true | Leaked | AS16276 | OVH SAS | OVH | 04/04/2026, 16:55:13 | 17/04/2026, 05:36:52 | Yes | Yes | APT1 Comment Crew, APT27, APT28, APT29, APT34, APT35, APT41, Donot Team, Earth Longzhi, Sandworm Team, Turla APT Group | CVE-2012-6708, CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2020-7656, CVE-2024-1322, CVE-2025-54352 | 07/04/2026, 20:38:41 | ovh.net |
| 118.196.43.•••:9443 | 小二 (🍵) | 🇨🇳 China mainland | Yes | true | Leaked | AS137718 | Beijing Volcano Engine Technology Co., Ltd. / AS4811 China Telecom (Group) | Beijing Volcano Engine Technology | 04/04/2026, 16:55:13 | 17/04/2026, 10:07:10 | Yes | No | - | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-44487, CVE-2023-48795, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387, CVE-2024-7347, CVE-2025-23419, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 10/04/2026, 17:49:24 | bytedance.com |
| 38.55.146.•••:443 | - | 🇺🇸 United States | Yes | true | Clean | AS400619 | AROSSCLOUD INC. | PEG Technology | 04/04/2026, 16:55:13 | 04/04/2026, 19:55:00 | - | - | - | - | - | - |
| 2408:8256:9286:2fbf:2e0:4cff:fe77:7447:18789 | - | 🇨🇳 China mainland | - | true | Clean | AS17816 | China Unicom IP network China169 Guangdong province | China Unicom | 04/04/2026, 16:55:13 | 04/04/2026, 19:54:59 | - | - | - | - | - | - |
| 84.247.133.•••:18789 | - | 🇩🇪 Germany | Yes | true | Leaked | AS51167 | Contabo GmbH | Contabo | 04/04/2026, 16:55:12 | 16/04/2026, 19:04:15 | Yes | Yes | APT15, APT28, APT29, APT31, APT34, APT41, Bitter APT, Bluenoroff, Callisto Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, Volt Typhoon | CVE-2016-20012, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728 | 08/04/2026, 01:04:42 | contabo.de, contabo.net |
| 3.227.49.•••:443 | - | 🇺🇸 United States | Yes | true | Clean | AS14618 | Amazon.com, Inc. | Amazon Web Services | 04/04/2026, 16:55:12 | 17/04/2026, 08:37:20 | No | No | - | CVE-2006-20001, CVE-2011-4718, CVE-2012-1171, CVE-2013-3735, CVE-2013-4113, CVE-2013-4248, CVE-2013-6420, CVE-2013-6501, CVE-2013-6712, CVE-2013-7327, CVE-2013-7345, CVE-2014-0133, CVE-2014-0185, CVE-2014-0207, CVE-2014-0236, CVE-2014-0237, CVE-2014-0238, CVE-2014-1943, CVE-2014-2020, CVE-2014-2270, CVE-2014-2497, CVE-2014-3478, CVE-2014-3479, CVE-2014-3480, CVE-2014-3487, CVE-2014-3515, CVE-2014-3538, CVE-2014-3587, CVE-2014-3597, CVE-2014-3616, CVE-2014-3668, CVE-2014-3669, CVE-2014-3670, CVE-2014-3710, CVE-2014-3981, CVE-2014-4049, CVE-2014-4670, CVE-2014-4698, CVE-2014-4721, CVE-2014-5120, CVE-2014-5459, CVE-2014-8142, CVE-2014-9425, CVE-2014-9426, CVE-2014-9427, CVE-2014-9652, CVE-2014-9653, CVE-2014-9705, CVE-2014-9709, CVE-2014-9767, CVE-2014-9912, CVE-2015-0231, CVE-2015-0232, CVE-2015-0235, CVE-2015-0273, CVE-2015-1351, CVE-2015-1352, CVE-2015-2301, CVE-2015-2305, CVE-2015-2325, CVE-2015-2326, CVE-2015-2331, CVE-2015-2348, CVE-2015-2783, CVE-2015-2787, CVE-2015-3152, CVE-2015-3307, CVE-2015-3329, CVE-2015-3330, CVE-2015-3411, CVE-2015-3412, CVE-2015-3414, CVE-2015-3415, CVE-2015-3416, CVE-2015-4021, CVE-2015-4022, CVE-2015-4024, CVE-2015-4025, CVE-2015-4026, CVE-2015-4116, CVE-2015-4147, CVE-2015-4148, CVE-2015-4598, CVE-2015-4599, CVE-2015-4600, CVE-2015-4601, CVE-2015-4602, CVE-2015-4603, CVE-2015-4604, CVE-2015-4605, CVE-2015-4642, CVE-2015-4643, CVE-2015-4644, CVE-2015-5589, CVE-2015-5590, CVE-2015-6831, CVE-2015-6832, CVE-2015-6833, CVE-2015-6834, CVE-2015-6835, CVE-2015-6836, CVE-2015-6837, CVE-2015-6838, CVE-2015-7803, CVE-2015-7804, CVE-2015-8835, CVE-2015-8838, CVE-2015-8865, CVE-2015-8867, CVE-2015-8873, CVE-2015-8874, CVE-2015-8876, CVE-2015-8877, CVE-2015-8879, CVE-2015-8935, CVE-2015-8994, CVE-2015-9253, CVE-2016-0742, CVE-2016-0746, CVE-2016-0747, CVE-2016-10158, CVE-2016-10159, CVE-2016-10161, CVE-2016-10397, CVE-2016-10712, CVE-2016-1247, CVE-2016-1903, CVE-2016-2554, CVE-2016-3141, CVE-2016-3142, CVE-2016-3185, CVE-2016-4070, CVE-2016-4342, CVE-2016-4343, CVE-2016-4450, CVE-2016-4537, CVE-2016-4538, CVE-2016-4539, CVE-2016-4540, CVE-2016-4541, CVE-2016-4542, CVE-2016-4543, CVE-2016-5093, CVE-2016-5094, CVE-2016-5095, CVE-2016-5096, CVE-2016-5114, CVE-2016-5399, CVE-2016-5768, CVE-2016-5769, CVE-2016-5770, CVE-2016-5771, CVE-2016-5772, CVE-2016-5773, CVE-2016-6174, CVE-2016-6288, CVE-2016-6289, CVE-2016-6290, CVE-2016-6291, CVE-2016-6292, CVE-2016-6294, CVE-2016-6295, CVE-2016-6296, CVE-2016-6297, CVE-2016-7124, CVE-2016-7125, CVE-2016-7126, CVE-2016-7127, CVE-2016-7128, CVE-2016-7129, CVE-2016-7130, CVE-2016-7131, CVE-2016-7132, CVE-2016-7411, CVE-2016-7412, CVE-2016-7413, CVE-2016-7414, CVE-2016-7416, CVE-2016-7417, CVE-2016-7418, CVE-2016-7478, CVE-2016-9137, CVE-2016-9138, CVE-2016-9934, CVE-2016-9935, CVE-2017-11142, CVE-2017-11143, CVE-2017-11144, CVE-2017-11145, CVE-2017-11147, CVE-2017-11628, CVE-2017-12933, CVE-2017-16642, CVE-2017-20005, CVE-2017-7272, CVE-2017-7529, CVE-2017-7890, CVE-2017-7963, CVE-2017-8923, CVE-2017-9224, CVE-2017-9225, CVE-2017-9226, CVE-2017-9229, CVE-2018-10545, CVE-2018-10546, CVE-2018-10547, CVE-2018-10548, CVE-2018-10549, CVE-2018-14851, CVE-2018-14883, CVE-2018-15132, CVE-2018-16845, CVE-2018-17082, CVE-2018-19395, CVE-2018-19396, CVE-2018-19520, CVE-2018-20783, CVE-2018-5711, CVE-2018-5712, CVE-2018-7584, CVE-2019-10081, CVE-2019-10082, CVE-2019-10092, CVE-2019-10098, CVE-2019-17567, CVE-2019-20372, CVE-2019-6977, CVE-2019-9020, CVE-2019-9021, CVE-2019-9023, CVE-2019-9024, CVE-2019-9517, CVE-2019-9637, CVE-2019-9638, CVE-2019-9639, CVE-2019-9641, CVE-2020-11984, CVE-2020-11993, CVE-2020-13938, CVE-2020-1927, CVE-2020-1934, CVE-2020-35452, CVE-2020-9490, CVE-2021-23017, CVE-2021-26690, CVE-2021-26691, CVE-2021-30641, CVE-2021-33193, CVE-2021-34798, CVE-2021-36160, CVE-2021-3618, CVE-2021-39275, CVE-2021-40438, CVE-2021-44224, CVE-2021-44790, CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-23943, CVE-2022-26377, CVE-2022-28330, CVE-2022-28614, CVE-2022-28615, CVE-2022-29404, CVE-2022-30556, CVE-2022-31628, CVE-2022-31629, CVE-2022-31813, CVE-2022-36760, CVE-2022-37436, CVE-2022-41741, CVE-2022-41742, CVE-2022-4900, CVE-2023-25690, CVE-2023-27522, CVE-2023-31122, CVE-2023-38709, CVE-2023-43622, CVE-2023-45802, CVE-2024-24795, CVE-2024-27316, CVE-2024-36387, CVE-2024-38472, CVE-2024-38473, CVE-2024-38474, CVE-2024-38475, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573, CVE-2024-40898, CVE-2024-42516, CVE-2024-43204, CVE-2024-43394, CVE-2024-47252, CVE-2025-23048, CVE-2025-49630, CVE-2025-49812, CVE-2025-53020, CVE-2025-55753, CVE-2025-58098, CVE-2025-59775, CVE-2025-65082, CVE-2025-66200 | 05/04/2026, 07:39:14 | - |
| 117.68.122.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS140527 | China Telecom | ChinaNet Anhui | 04/04/2026, 16:55:12 | 17/04/2026, 07:07:04 | Yes | - | - | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 08/04/2026, 08:38:12 | bj189.cn, 118114.cn, ctwing.cn, chinatelecom.com.cn, chinatelecom.cn, new-gm.cn, 189.cn, 189free.cn, ideal.sh.cn, daqu.com.cn, ctyun.cn |
| 171.83.56.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS137266 | CHINATELECOM Hubei province Wuhan 5G network | ChinaNet Hubei | 04/04/2026, 16:55:11 | 10/04/2026, 10:57:38 | Yes | No | - | - | 10/04/2026, 10:59:59 | bj189.cn, 118114.cn, ctwing.cn, chinatelecom.com.cn, chinatelecom.cn, new-gm.cn, 189.cn, 189free.cn, ideal.sh.cn, daqu.com.cn, ctyun.cn |
| 91.98.141.•••:18789 | - | 🇩🇪 Germany | Yes | true | Clean | AS24940 | Hetzner Online GmbH | Hetzner | 04/04/2026, 16:55:11 | 14/04/2026, 06:04:53 | No | No | - | CVE-2016-20012, CVE-2021-36368, CVE-2021-41617, CVE-2022-3590, CVE-2023-22622, CVE-2023-2745, CVE-2023-38000, CVE-2023-38408, CVE-2023-39999, CVE-2023-48795, CVE-2023-51385, CVE-2023-5561, CVE-2023-5692, CVE-2024-31111, CVE-2024-31210, CVE-2024-42516, CVE-2024-43204, CVE-2024-43394, CVE-2024-4439, CVE-2024-47252, CVE-2024-6305, CVE-2024-6306, CVE-2024-6307, CVE-2024-6387, CVE-2025-23048, CVE-2025-26465, CVE-2025-32728, CVE-2025-49630, CVE-2025-49812, CVE-2025-53020, CVE-2025-54352, CVE-2025-55753, CVE-2025-58098, CVE-2025-58246, CVE-2025-58674, CVE-2025-59775, CVE-2025-61984, CVE-2025-61985, CVE-2025-65082, CVE-2025-66200 | 08/04/2026, 09:23:26 | - |
| 38.127.47.•••:18789 | - | 🇺🇸 United States | Yes | true | Clean | AS18978 | Enzu Inc | Enzu | 04/04/2026, 16:55:11 | 17/04/2026, 02:36:40 | No | Yes | APT15, APT31, APT37, APT39, Bitter APT, Bluenoroff, Donot Team, Gamaredon Group, Gaza Cybergang, Inception Framework, Kimsuky, MuddyWater Group, Salt Typhoon, SideWinder APT | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51385 | 10/04/2026, 13:15:48 | - |
| 161.35.215.•••:18789 | - | 🇩🇪 Germany | Yes | true | Leaked | AS14061 | DigitalOcean, LLC | DigitalOcean | 04/04/2026, 16:55:11 | 16/04/2026, 01:22:51 | Yes | Yes | APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MoustachedBouncer, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2007-4559, CVE-2013-0340, CVE-2015-20107, CVE-2016-10708, CVE-2016-20012, CVE-2016-3189, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2018-25032, CVE-2019-12900, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-10735, CVE-2020-12062, CVE-2020-14145, CVE-2020-15778, CVE-2021-23017, CVE-2021-28041, CVE-2021-28861, CVE-2021-3618, CVE-2021-36368, CVE-2021-3733, CVE-2021-3737, CVE-2021-41617, CVE-2021-4189, CVE-2022-0391, CVE-2022-37454, CVE-2022-40468, CVE-2022-41741, CVE-2022-41742, CVE-2022-42919, CVE-2022-45061, CVE-2023-24329, CVE-2023-27043, CVE-2023-28531, CVE-2023-38408, CVE-2023-40533, CVE-2023-44487, CVE-2023-48795, CVE-2023-49606, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2024-7347, CVE-2025-26465, CVE-2025-32728 | 10/04/2026, 11:45:21 | warpspeedvpn.com |
| 58.37.19.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS4812 | China Telecom (Group) | ChinaNet Shanghai | 04/04/2026, 16:55:11 | 16/04/2026, 11:29:51 | - | - | - | - | - | - |
| 47.77.234.•••:18789 | - | 🇺🇸 United States | Yes | true | Leaked | AS45102 | Alibaba (US) Technology Co., Ltd. | Alibaba Cloud | 04/04/2026, 16:55:11 | 14/04/2026, 05:19:53 | Yes | No | - | CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 14/04/2026, 01:35:38 | hichina.com, alibaba-inc.com |
| 45.207.201.•••:80 | - | 🇭🇰 Hong Kong | Yes | true | Clean | AS8796 | FASTNET DATA INC | Vapeline Technology | 04/04/2026, 16:55:11 | 16/04/2026, 01:23:36 | - | - | - | - | - | - |
| 167.150.153.•••:18789 | - | 🇵🇦 Panama | Yes | true | Clean | AS212105 | WildSage Labs Inc. | WildSage Labs | 04/04/2026, 16:55:10 | 16/04/2026, 19:04:22 | - | - | - | - | - | - |
| 209.38.173.•••:18789 | - | 🇺🇸 United States | Yes | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 04/04/2026, 16:55:10 | 14/04/2026, 03:04:29 | No | Yes | APT15, APT17, APT28, APT29, APT31, APT34, APT35, APT36, APT37, APT39, APT40, APT41, APT45, Bitter APT, Bluenoroff, Callisto Group, Carbanak, ChamelGang, CloudSorcerer, Daggerfly APT, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-39894, CVE-2024-6387 | 07/04/2026, 21:26:17 | - |
| 47.254.216.•••:80 | - | 🇲🇾 Malaysia | Yes | true | Clean | AS45102 | Alibaba (US) Technology Co., Ltd. | Alibaba Cloud Malaysia | 04/04/2026, 16:55:10 | 16/04/2026, 12:15:23 | No | No | - | CVE-2016-20012, CVE-2019-16905, CVE-2020-12062, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-3618, CVE-2021-36368, CVE-2021-41617, CVE-2022-41741, CVE-2022-41742, CVE-2023-38408, CVE-2023-44487, CVE-2023-48795, CVE-2023-51385, CVE-2024-7347, CVE-2025-23419, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 13/04/2026, 20:20:05 | - |
| 101.34.252.•••:8443 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud Computing | 04/04/2026, 16:55:10 | 16/04/2026, 18:18:37 | Yes | Yes | APT-C-23, APT15, APT28, APT29, APT31, APT34, APT35, APT37, APT39, APT41, Bitter APT, Bluenoroff, Callisto Group, Cobalt Group, Donot Team, El-Machete, Gamaredon Group, Gaza Cybergang, Ghostwriter, Hafnium Group, Inception Framework, Kimsuky, Lazarus Group, MuddyWater Group, Mustang Panda, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers, Turla APT Group, Volt Typhoon | CVE-2016-20012, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-38408, CVE-2023-44487, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385 | 09/04/2026, 23:31:06 | tencent.com |
| 92.113.148.•••:443 | - | 🇺🇦 Ukraine | Yes | true | Clean | AS44803 | Webdock.io ApS | Ukrtelecom | 04/04/2026, 16:55:10 | 05/04/2026, 08:20:10 | - | - | - | - | - | - |
| 60.186.100.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Clean | AS4134 | Chinanet | ChinaNet Hangzhou | 04/04/2026, 16:55:10 | 04/04/2026, 19:54:57 | - | - | - | - | - | - |
| 130.61.47.•••:18789 | - | 🇺🇸 United States | Yes | true | Leaked | AS31898 | Oracle Corporation | Oracle Cloud | 04/04/2026, 16:55:10 | 17/04/2026, 19:28:36 | Yes | Yes | Salt Typhoon | CVE-2016-20012, CVE-2019-16905, CVE-2020-14145, CVE-2020-15778, CVE-2021-36368, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 08/04/2026, 06:23:03 | healtheintent.com, purewellness.com, cerner.ae, retek.com, tryfoexnow.com, moatads.com, oraclefusion.com, connectinc.com, inquira.com, portal.com, oracle.com, hiedirectconnect.org, maxymiser.net, oraclecloudservices.com, rsys2.net, hyperroll.com, nor1.com, oxygen.systems, oraclegovcloud.com, orcale.com, oraclemobile.com, sun.co.in, openair.co, oraclepdemos.com, stellent.com, siebel.com, cerner.net, oracle-cloud.com, docucorp.com, mvalent.com, elementfusion.com, netsuiteforms.com, oracleemaildelivery.com, oraclecloud.com, en25.com, solaris.com, rightnowtech.com, think.com, ipapp.com, jdedwards.com, tiger-institute.org, zenedge.com, skire.com, sun.com, sales.com, fyleio.com, push.io, estara.com, tekelec.com, textura.com, paymyhealthbill.com, dyndns.com, java.net, optika.com, jcp.org, smed.com, cernerenviza-tw.com, datafox.com, recruitmax.com, decisioneering.com, adiinsights.com, stortek.com, seebeyond.com, livelook.com, openjdk.org, virtualbox.org, dyn.com, oraclehealth.com, aimsystems.com, sunworld.com, plumtree.com, storagetek.com, oracledatacloud.com |
| 43.165.166.•••:443 | - | 🇯🇵 Japan | Yes | true | Clean | AS132203 | Tencent Building, Kejizhongyi Avenue | Aceville Pte Ltd | 04/04/2026, 16:55:10 | 17/04/2026, 10:06:34 | - | - | - | - | - | - |
| 34.27.89.•••:2200 | - | 🇺🇸 United States | Yes | true | Clean | AS396982 | Google LLC | 04/04/2026, 16:55:10 | 04/04/2026, 19:54:55 | - | - | - | - | - | - | |
| 198.46.84.•••:8084 | - | 🇺🇸 United States | Yes | true | Leaked | AS54641 | InMotion Hosting, Inc. | InMotion Hosting | 04/04/2026, 16:55:10 | 16/04/2026, 01:23:02 | Yes | No | - | - | 07/04/2026, 17:07:59 | avera.com, inmotionhosting.com |
| 13.211.37.•••:443 | - | 🇦🇺 Australia | Yes | true | Clean | AS16509 | Amazon.com, Inc. | Amazon Corporate Services | 04/04/2026, 16:55:10 | 04/04/2026, 19:54:55 | No | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728 | 04/04/2026, 19:09:55 | - |
| 49.232.205.•••:18789 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud | 04/04/2026, 16:55:09 | 17/04/2026, 04:51:51 | Yes | Yes | APT37, El-Machete | - | 04/04/2026, 19:10:12 | tencent.com |
| 47.114.75.•••:443 | - | 🇨🇳 China mainland | Yes | true | Clean | AS37963 | Hangzhou Alibaba Advertising Co.,Ltd. | Alisoft | 04/04/2026, 16:55:09 | 16/04/2026, 13:00:57 | No | No | - | CVE-2016-20012, CVE-2019-16905, CVE-2020-14145, CVE-2020-15778, CVE-2021-3618, CVE-2021-36368, CVE-2021-41617, CVE-2022-41741, CVE-2022-41742, CVE-2023-38408, CVE-2023-44487, CVE-2023-48795, CVE-2023-51385, CVE-2024-7347, CVE-2025-23419, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 04/04/2026, 19:10:14 | - |
| 101.35.91.•••:6001 | - | 🇨🇳 China mainland | Yes | true | Leaked | AS45090 | Shenzhen Tencent Computer Systems Company Limited | Tencent Cloud Computing | 04/04/2026, 16:55:09 | 16/04/2026, 19:50:10 | Yes | Yes | APT37, El-Machete | CVE-2023-44487, CVE-2024-7347, CVE-2025-23419 | 04/04/2026, 19:10:17 | tencent.com |
| 43.156.231.•••:18789 | - | 🇸🇬 Singapore | Yes | true | Leaked | AS132203 | Tencent Building, Kejizhongyi Avenue | Aceville Pte Ltd | 04/04/2026, 16:55:09 | 17/04/2026, 23:57:37 | Yes | Yes | APT15, APT17, APT28, APT31, APT35, APT36, APT37, APT39, APT45, Bitter APT, Bluenoroff, CloudSorcerer, Cobalt Group, Daggerfly APT, Donot Team, El-Machete, Gamaredon Group, Gaza Cybergang, Inception Framework, Kimsuky, MuddyWater Group, Mustang Panda, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SideWinder APT, The Shadow Brokers | CVE-2016-10708, CVE-2017-15906, CVE-2018-15473, CVE-2018-15919, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617, CVE-2023-28531, CVE-2023-38408, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-6387, CVE-2025-26465, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 04/04/2026, 19:10:29 | tencent.com |
| 18.176.153.•••:18789 | - | 🇯🇵 Japan | Yes | true | Clean | AS16509 | Amazon.com, Inc. | Amazon Web Services Japan | 04/04/2026, 16:55:09 | 11/04/2026, 19:41:28 | No | No | - | CVE-2024-39894, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 04/04/2026, 19:10:34 | - |
| 62.171.147.•••:18789 | - | 🇫🇷 France | Yes | true | Leaked | AS51167 | Contabo GmbH | Contabo | 04/04/2026, 16:55:09 | 17/04/2026, 18:49:27 | Yes | Yes | APT14, APT15, APT17, APT28, APT29, APT31, APT34, APT35, APT36, APT37, APT40, APT41, APT45, Bitter APT, Bluenoroff, Callisto Group, Carbanak, ChamelGang, CloudSorcerer, Cobalt Group, Daggerfly APT, Donot Team, Gamaredon Group, Gaza Cybergang, Hafnium Group, Inception Framework, Kimsuky, Lazarus Group, MuddyWater Group, Patchwork, RomCom Group, Salt Typhoon, Sandworm Team, Sea Turtle Group, SharpPanda, SideWinder APT, The Shadow Brokers, Volt Typhoon | CVE-2006-20001, CVE-2016-20012, CVE-2020-12062, CVE-2020-14145, CVE-2020-15778, CVE-2021-28041, CVE-2021-36368, CVE-2021-41617, CVE-2022-22719, CVE-2022-22720, CVE-2022-22721, CVE-2022-23943, CVE-2022-26377, CVE-2022-28330, CVE-2022-28614, CVE-2022-28615, CVE-2022-29404, CVE-2022-30556, CVE-2022-31813, CVE-2022-36760, CVE-2022-37436, CVE-2023-25690, CVE-2023-27522, CVE-2023-28531, CVE-2023-31122, CVE-2023-38408, CVE-2023-38709, CVE-2023-45802, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2024-24795, CVE-2024-27316, CVE-2024-38472, CVE-2024-38473, CVE-2024-38474, CVE-2024-38475, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573, CVE-2024-39894, CVE-2024-40898, CVE-2024-6387, CVE-2025-26465, CVE-2025-26466, CVE-2025-32728, CVE-2025-61984, CVE-2025-61985 | 04/04/2026, 19:10:35 | contaboserver.net, contabo.de, contabo.net |
| 138.197.8.•••:443 | - | 🇺🇸 United States | Yes | true | Clean | AS14061 | DigitalOcean, LLC | DigitalOcean | 04/04/2026, 16:55:09 | 17/04/2026, 18:49:29 | No | No | - | CVE-2018-20685, CVE-2019-16905, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-14145, CVE-2021-41617, CVE-2024-39894, CVE-2024-6387, CVE-2025-26466 | 04/04/2026, 19:10:38 | - |